TIL that Code Signing policies had changed for the worst. Signing is now more expensive, requires a physical device and no longer can be a automated step on build agents such as GitHub Actions. π΅βπ«
Windows code signing has one big problem: it's too expensive π«° and difficult to deal with for most open source projects, where it's often coming out of someone's personal money, not from a business that can well afford it